Input validation error in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-8030
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote user to prevent another user from modifying group settings.
The vulnerability exists due to improper input validation in namespace transfer when validating group URL slugs. A remote user can use an improperly validated group URL slug during a namespace transfer to prevent another user from modifying group settings.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-8030
GitLab Enterprise Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2